Lucene search

K
cve[email protected]CVE-2023-6489
HistoryApr 12, 2024 - 1:15 a.m.

CVE-2023-6489

2024-04-1201:15:57
CWE-400
web.nvd.nist.gov
33
denial of service
gitlab
ce/ee
vulnerability
resource spike

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

4.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

CNA Affected

[
  {
    "vendor": "GitLab",
    "product": "GitLab",
    "repo": "git://[email protected]:gitlab-org/gitlab.git",
    "versions": [
      {
        "version": "16.7.7",
        "status": "affected",
        "lessThan": "16.8.6",
        "versionType": "semver"
      },
      {
        "version": "16.9",
        "status": "affected",
        "lessThan": "16.9.4",
        "versionType": "semver"
      },
      {
        "version": "16.10",
        "status": "affected",
        "lessThan": "16.10.2",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

4.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%